🔒 Privacy Policy

NetCam

Last Updated: August 26, 2026

✓ Local-First · No Tracking · No Advertising
🛡️

Your Camera Data Stays Under Your Control

NetCam turns your iOS or Android device into a camera that you control from a browser or automation client on your local network. Captured photos, live preview frames, camera settings, and device-status information are not uploaded to ScienceSoft e.U. or a developer-operated cloud service. They remain on your device or travel directly to clients that you authorize on your local network. The app contains no analytics, tracking, advertising, or crash-reporting framework.

What This Means for You

📷

Photos Stay Local

Photos are kept in the app's private storage and are shared only with authenticated clients you connect on your LAN

📵

No Developer Collection

No NetCam account, cloud photo library, telemetry endpoint, or remote developer database

🏠

Local Network Operation

The built-in web server, WebSocket API, image transfer, and service discovery operate directly on your local network

🚫

No Analytics or Ads

No Firebase, Crashlytics, Sentry, Google Analytics, AdMob, IDFA/AAID collection, or advertising SDK

Scope of This Policy

This policy describes the NetCam mobile app, its embedded control website, and its local automation API. It distinguishes between data processed locally by the app and data that may be processed independently by Apple or Google when you use their app-store services.

Camera images can contain personal data. NetCam processes that content only to provide the features you request; ScienceSoft e.U. does not receive it. If you use NetCam to photograph other people or to process data for an organization, you are responsible for having an appropriate legal basis, giving any required notice, and securing access to the app and your local network.

How the App Works

NetCam runs on iOS and Android. The phone hosts a control site or a TLS-only WebSocket automation API. A browser or compatible client connects directly to the phone over the same reachable local network.

  • NetCam: choose a camera and resolution, adjust supported focus, exposure, zoom, flash, and image-quality controls, and request single or scheduled captures
  • Local gallery: list, preview, crop for download, download, export as ZIP, or delete photos stored by the app
  • Live preview: send JPEG preview frames directly to connected local clients
  • Local discovery: advertise the running service through Bonjour on iOS or Network Service Discovery on Android
  • No cloud dependency: camera operation and photo transfer do not require a NetCam account or a developer-operated server

Data Processed by NetCam

Depending on the features you use, the app processes the following categories on your device and, where stated, sends them to your authenticated local client:

  • Photos and preview frames: JPEG images captured by the selected camera. Cached originals include a locally generated identifier, capture timestamp, and file size. Photos, cropped derivatives, ZIP exports, and preview frames are sent only in response to requests from an authenticated local browser or API client.
  • Camera information and controls: camera names, lens direction, supported resolutions and capabilities, selected camera, focus and exposure points, zoom, flash, JPEG quality, and camera readiness.
  • Device-status information: battery level and charging state, thermal state (and Android battery-sensor temperature where available), total and free storage, app foreground state, camera ready/busy state, connected-client counts, and sampling time. This status is shown only to authenticated local clients.
  • Local service information: the selected local IP address and port, HTTP or HTTPS/WSS mode, protocol path, and service name. Unless you configure a host name, the device model may be used as the visible service name.
  • Authentication and security data: the password you set, random session tokens, recent login-attempt IP addresses held briefly in memory for rate limiting, and locally generated certificate and private-key material when HTTPS or the automation API is used.
  • App settings: gallery limit, server address and port, host name, selected camera and resolution, HTTPS/API/reliability options, layout, theme, headless mode, and screen-awake preference.
  • Purchase metadata: for a completed or restored one-time licence purchase, the app stores the store product identifier, currency, price, and purchase date locally. The app does not receive or store your payment-card or bank-account details.

Network Connections and Local Sharing

NetCam does not send photos or device status to ScienceSoft e.U. The following network activity occurs only to provide features you choose to use:

  • Embedded control website: the app accepts HTTP or optional HTTPS connections on the local address and port you select. After password authentication, a client can control the camera, view device status, receive live preview frames, and access cached photos.
  • Automation API: when enabled and started, the app accepts authenticated TLS WebSocket (wss) connections on your local network. API responses and events can include camera status, device status, preview frames, and captured images.
  • Bonjour / Android NSD: while a server is running, the app advertises its service name, service type, port, path, and protocol to devices that can observe discovery traffic on the local network. This makes the service easier to find.
  • Apple App Store / Google Play: opening the licence screen, checking product availability, buying, or restoring a licence communicates with the platform store. Apple or Google processes the store account, transaction, device, and payment information under its own terms and privacy policy.
  • User-opened external links: links in the About and Projects screens open in your browser only when you select them. The destination site then receives ordinary web request data such as your IP address and browser information under its own privacy policy.

Security notice: HTTP traffic is not encrypted. Use NetCam only on a network you trust, set a strong and unique password, stop the server when it is not needed, and prefer HTTPS or the TLS-only automation API where practical. Anyone who obtains valid local access and the password may be able to operate the camera and download photos.

Storage, Retention, and Deletion

  • Cached photos: JPEG files are stored in the app's private documents area. The default gallery limit is 20 photos. When the configured limit is exceeded, the oldest files are removed automatically. You can delete individual or selected photos from the web gallery, clear the full photo cache in Settings, or uninstall the app.
  • Ordinary preferences: settings are stored using the platform's app-preference storage until you change them, clear the app's data, or uninstall the app, subject to your operating system's backup and restore behavior.
  • Secure local storage: the web password, purchase metadata, and TLS private keys/certificates are stored through iOS Keychain or Android secure storage. Platform backup, restore, or Keychain behavior may retain or restore some secure values independently of the app. You can change the password in Settings; clearing app data or managing platform backups may also be necessary to remove restored values.
  • Browser authentication: the local control site sets one strictly scoped, HTTP-only session cookie named cc_session. The matching token is held only in the app's memory, expires after 24 hours of inactivity, and is invalidated by logout, server stop, password change, or a newer login.
  • Temporary operational history: login rate-limit entries, capture-job state, capture-session state, previews, and other runtime data are held in memory and are bounded or removed when they expire or the relevant server stops. Completed capture jobs become eligible for removal after 10 minutes and completed capture sessions after 30 minutes; cleanup occurs when the relevant registry is next used or the server stops.
  • Installed web-app data: a browser may store the selected light/dark theme in local storage and cache static interface assets for the optional Progressive Web App. Camera operations, authenticated pages, API responses, and photos are not placed in that static asset cache. You can clear this data using your browser's site-data controls.
  • Store records: Apple or Google may retain transaction records according to its own legal obligations and privacy policy. Removing local app data does not delete records maintained by the platform store.

Permissions

The app requests or declares only the platform permissions needed for its features:

iOS

  • Camera: to show the preview and take the photos you request
  • Local network: to accept connections from your browser or API client and publish the service through Bonjour
  • No microphone, location, contacts, Bluetooth, calendar, HealthKit, tracking, or Photos library permission is requested

Android

  • CAMERA: to show the preview and take the photos you request
  • INTERNET: to run the embedded local server and communicate with clients on your local network
  • ACCESS_LOCAL_NETWORK: to accept local-network connections on Android versions that enforce this runtime permission
  • com.android.vending.BILLING: to offer and restore the optional one-time licence through Google Play
  • No microphone, location, contacts, nearby-device, Bluetooth, or media-library permission is declared

In-App Purchase

NetCam offers an optional one-time licence through StoreKit on iOS and Google Play Billing on Android. The licence removes the app-logo watermark from downloaded photos; camera operation and locally cached originals remain available without it. The store handles the payment transaction. After a successful purchase or restore, NetCam saves only the local metadata described above to recognize the entitlement on that device. For details about store processing, review the Apple Privacy Policy or Google Privacy Policy.

Third-Party Services and SDKs

The app uses Apple StoreKit or Google Play Billing for the optional in-app purchase. It also uses Flutter packages that run within the app to provide camera access, local storage, cryptography, image processing, archive creation, device information, and screen-awake functionality. These packages do not create a developer-operated cloud service.

NetCam does not include Firebase, Sentry, Crashlytics, Google Analytics, Facebook SDK, AdMob, Branch, AppsFlyer, IDFA/AAID collection, remote configuration, push notifications, or any other tracking or advertising framework.

Data Controller

The provider responsible for NetCam and for any personal data sent directly to us, such as a support email, is:

  • Company: ScienceSoft e.U.
  • Address: Oberzellergasse 12/13, 1030 Vienna, Austria
  • Commercial Register: FN 644834k
  • VAT ID: ATU60406778
  • Email: peter.sauer@flutterdev.app

ScienceSoft e.U. is not the recipient of photos, preview frames, device-status data, local passwords, or local API traffic. If you deploy NetCam in a business or organizational context, you or your organization may be the controller for content processed through the app.

Legal Bases

To the extent ScienceSoft e.U. processes personal data in connection with NetCam, we rely on Article 6(1)(b) GDPR where processing is necessary to respond to a request or provide a service you requested, and Article 6(1)(f) GDPR for our legitimate interests in providing support, operating and securing this policy website, and protecting our legal rights. We do not use app data for advertising or profiling.

The photos and technical data processed solely on your device or exchanged with your own local clients are not sent to us. Apple and Google determine their own legal bases for the store data they process under their respective privacy policies.

This Policy Page and External Links

This page is part of the FlutterDev website. It uses first-party scripts for functions such as theme switching and does not use analytics, advertising trackers, or third-party cookies. The hosting web server may process standard technical log data, such as IP address, browser type, requested page, and access time, to deliver and secure the website.

Links to Apple, Google, GitHub, app stores, or other external sites are governed by the privacy policies of those destinations. We do not control their data practices.

Children's Privacy

NetCam is a general-purpose camera utility and is not directed to children. We do not knowingly collect personal data from children through a NetCam account or developer server because the app has neither. A device owner can nevertheless capture images that include children. The person operating the camera is responsible for appropriate supervision, consent, notice, and lawful use of those images.

Your Choices and Rights

  • Choose whether to start a local server (which advertises itself while running), enable the automation API, use HTTPS, or make a store purchase
  • Delete photos individually, in batches, automatically through the cache limit, or all at once using the clear-cache control
  • Change the local password and server settings, log out local browser clients, stop the server, clear browser site data, or uninstall the app
  • Contact us to request access, correction, deletion, restriction, objection, or portability for personal data that you have directly provided to ScienceSoft e.U., subject to applicable law and any required retention
  • Exercise store-related rights directly with Apple or Google for data controlled by that platform

California notice: ScienceSoft e.U. does not sell or share NetCam app data for cross-context behavioral advertising and does not use it for targeted advertising. You may contact us using the address below with any applicable privacy request.

Changes to This Privacy Policy

We may update this Privacy Policy when NetCam's features, data practices, or legal obligations change. The date at the top of this page identifies the latest version. Material changes apply prospectively from the updated date unless applicable law requires otherwise.

Contact Us

If you have questions about this Privacy Policy or want to exercise an applicable privacy right, please contact us:

Supervisory Authority

You have the right to lodge a complaint with a competent data protection authority. The Austrian supervisory authority is:

  • Austrian Data Protection Authority (Österreichische Datenschutzbehörde)
  • Address: Barichgasse 40-42, 1030 Vienna, Austria
  • Email: dsb@dsb.gv.at
  • Website: www.dsb.gv.at

Our Commitment

At ScienceSoft e.U., we build NetCam so that your camera content remains on hardware and networks you control. The app has no tracking or advertising frameworks, does not require a developer account or cloud, and gives you direct controls for local access and photo deletion.